机械工业高技术设备网络安全风险分析系统研究

Svetlana Suloyeva, S. Grishunin, E. Burova
{"title":"机械工业高技术设备网络安全风险分析系统研究","authors":"Svetlana Suloyeva, S. Grishunin, E. Burova","doi":"10.1145/3372177.3373310","DOIUrl":null,"url":null,"abstract":"The paper is dedicated to developing a system for identifying and assessing cyber-risks to support investment decision-making in a machine industry enterprise. It is designed for projects related to high-tech equipment development and introduction. The problem is acute because the existing methods of cyber-risk analysis have some drawbacks, which prevent them from being used at a time of growing information threats. A structural-logical scheme for the cyber-risk analysis system has been developed, and detailed descriptions are provided for some blocks of the system and their tools. The research methods include system approach to problem-studying, analysis of fundamental statements given in literature, and analysis of the existing tools used in practice for solving these problems. The presented system has some advantages in comparison with such common approaches as risk maps or factor analysis of information risks (FAIR). Since it is built on risk-control principles, it ensures that all actions of management concerning cyber-risk-control are integrated and coordinated. The system also contains effective tools and methods for assessing cyber-risks in quantitative terms, calculating a consolidated effect with due consideration of risks, assessing the impact this effect makes on the strategic goal indicator of a project, comparing project implementation scenarios given cyber threats with risk appetite to evaluate the acceptability of the project. These advantages make the system dynamic and integrative, reactive to the changes of the cyberspace and emergence of new threats. It can have a substantial practical application in managing investment projects related to the development and introduction of high-tech equipment in enterprises of the sector.","PeriodicalId":368926,"journal":{"name":"Proceedings of the 2019 International SPBPU Scientific Conference on Innovations in Digital Economy","volume":"126 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-10-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Developing a Cybersecurity Risk Analysis System for High-Tech Equipment in Machine Industry\",\"authors\":\"Svetlana Suloyeva, S. Grishunin, E. Burova\",\"doi\":\"10.1145/3372177.3373310\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The paper is dedicated to developing a system for identifying and assessing cyber-risks to support investment decision-making in a machine industry enterprise. It is designed for projects related to high-tech equipment development and introduction. The problem is acute because the existing methods of cyber-risk analysis have some drawbacks, which prevent them from being used at a time of growing information threats. A structural-logical scheme for the cyber-risk analysis system has been developed, and detailed descriptions are provided for some blocks of the system and their tools. The research methods include system approach to problem-studying, analysis of fundamental statements given in literature, and analysis of the existing tools used in practice for solving these problems. The presented system has some advantages in comparison with such common approaches as risk maps or factor analysis of information risks (FAIR). Since it is built on risk-control principles, it ensures that all actions of management concerning cyber-risk-control are integrated and coordinated. The system also contains effective tools and methods for assessing cyber-risks in quantitative terms, calculating a consolidated effect with due consideration of risks, assessing the impact this effect makes on the strategic goal indicator of a project, comparing project implementation scenarios given cyber threats with risk appetite to evaluate the acceptability of the project. These advantages make the system dynamic and integrative, reactive to the changes of the cyberspace and emergence of new threats. It can have a substantial practical application in managing investment projects related to the development and introduction of high-tech equipment in enterprises of the sector.\",\"PeriodicalId\":368926,\"journal\":{\"name\":\"Proceedings of the 2019 International SPBPU Scientific Conference on Innovations in Digital Economy\",\"volume\":\"126 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-10-24\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the 2019 International SPBPU Scientific Conference on Innovations in Digital Economy\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3372177.3373310\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2019 International SPBPU Scientific Conference on Innovations in Digital Economy","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3372177.3373310","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

本文致力于开发一个识别和评估网络风险的系统,以支持机械工业企业的投资决策。它是为与高科技设备开发和引进有关的项目设计的。问题之所以尖锐,是因为现有的网络风险分析方法存在一些缺陷,使得它们无法在信息威胁日益增长的时代得到应用。提出了网络风险分析系统的结构逻辑方案,并对系统的部分模块及其使用的工具进行了详细的描述。研究方法包括问题研究的系统方法,对文献中给出的基本陈述的分析,以及分析在实践中用于解决这些问题的现有工具。与风险图或信息风险因子分析(FAIR)等常用方法相比,该系统具有一定的优势。由于它是建立在风险控制原则的基础上的,因此它确保了与网络风险控制有关的所有管理行动的整合和协调。该系统还包含有效的工具和方法,用于定量评估网络风险,计算适当考虑风险的综合效应,评估该效应对项目战略目标指标的影响,将网络威胁下的项目实施场景与风险偏好进行比较,以评估项目的可接受性。这些优势使该系统具有动态性和整体性,能够对网络空间的变化和新威胁的出现作出反应。它在管理行业企业开发和引进高科技设备的投资项目方面具有重要的实际应用价值。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Developing a Cybersecurity Risk Analysis System for High-Tech Equipment in Machine Industry
The paper is dedicated to developing a system for identifying and assessing cyber-risks to support investment decision-making in a machine industry enterprise. It is designed for projects related to high-tech equipment development and introduction. The problem is acute because the existing methods of cyber-risk analysis have some drawbacks, which prevent them from being used at a time of growing information threats. A structural-logical scheme for the cyber-risk analysis system has been developed, and detailed descriptions are provided for some blocks of the system and their tools. The research methods include system approach to problem-studying, analysis of fundamental statements given in literature, and analysis of the existing tools used in practice for solving these problems. The presented system has some advantages in comparison with such common approaches as risk maps or factor analysis of information risks (FAIR). Since it is built on risk-control principles, it ensures that all actions of management concerning cyber-risk-control are integrated and coordinated. The system also contains effective tools and methods for assessing cyber-risks in quantitative terms, calculating a consolidated effect with due consideration of risks, assessing the impact this effect makes on the strategic goal indicator of a project, comparing project implementation scenarios given cyber threats with risk appetite to evaluate the acceptability of the project. These advantages make the system dynamic and integrative, reactive to the changes of the cyberspace and emergence of new threats. It can have a substantial practical application in managing investment projects related to the development and introduction of high-tech equipment in enterprises of the sector.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Regional differentiation of digital economy development in the Russian Federation Features of the analysis of business processes of the company (on the example of customer service in a travel agency) Digitalization of the educational process: problematic issues in the context of the development of the digital economy Developing a Cybersecurity Risk Analysis System for High-Tech Equipment in Machine Industry Evaluation of Digital Transformation of Government: Russian and international systems of indicators
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1